Jul 2026
What Can Be Enforced? A Theory of Certified Runtime Safety for Tool-Using Agents
This work states that relative to fixed oracle predicates, a deterministic gate enforces exactly the nonempty safety policies whose good prefixes its register model recognizes; policy nontriviality is undecidable with two decrementable counters but in PSPACE for a separable monotone fragment.
S. Ray
· arXiv.org · 0 citations